1.1: Risk Assessment (Doshi) Flashcards
What are the elements of risk?
(1) Probability
(2) Impact
(3) Vulnerability
(4) Threat
What is the risk formula?
Risk = Probability X Impact
or
Risk = Asset Value X Vulnerability X Threat
What is a vulnerability?
Vulnerability is a weakness or gap in our protection efforts. Vulnerability can be in form of weak coding, missing anti-virus, weak access control and other related factors. Vulnerabilities can be controlled by us.
Vulnerability means weak or defenseless
What is a threat?
A threat is what we’re trying to protect against.Our enemy could be Earthquake, Fire, Hackers, Malware, System Failure, Criminals and many other unknown forces. Threats are not in our control.
Threat means something that can exploit the weakness
Is there a threat for a useless system?
Even though vulnerability is high for a useless system, threats do not exist.
Steps of Risk assessment are:
1- Understand the business environment
2- Identify critical Assets/Processes.
3- Identify relevant risks (Vulnerability and threat)
4 - Prioritize the risks in order of criticality/ Risk Prioritization
5- Evaluate various control mechanisms available
6 - Apple relevant controls/ Risk Treatment
IS Auditor identified certain threats and vulnerabilities in a business process. Next, an IS auditor should:
A. identify stakeholder for that business process.
B. identify information assets and the underlying systems.
C. disclose the threats and impacts to management.
D. identify and evaluate the existing controls.
C. disclose the threats and impacts to management.
Avoid confusion between Threat and vulnerability
1- A threat is what we’re trying to protect against. Threats are not in our control.
2- Vulnerability is a weakness or gap in our protection efforts. Vulnerabilities can be controlled by us.
Absence of proper security measures represents a (n):
A. threat.
B. asset.
C. impact.
D. vulnerability.
D. vulnerability.
Types of Risk are:
(1) Inherent
(2) Residual
(3) Detection
(4) Control
Inherent Risk
The risk that an activity would pose if no controls or other mitigating factors were in place (the gross risk or risk before controls).
Residual Risk
The risk that remains after controls are taken into account (the net risk or risk after controls).
Detection risk
Detection risk is the possibility that an auditor will overlook errors or exceptions during an audit. Detection risk should carried at the beginning of risk assessment.
Control risk
Risk that a misstatement could occur but may not be detected and corrected or prevented by entity’s internal control mechanism
Control risk is the probability that financial statements are materially misstated, due to failures in the system of controls used by a business
Audit Risk
The risk that the financial statements are materially incorrect, even though the audit opinion states that the financial reports are free of any material misstatements